Bug hunt ledger: Bundler (RubyGems) #316
Replies: 8 comments
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API. I used a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run Tested: main Setup: a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Bundler (RubyGems) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Bundler (RubyGems) version cells for |
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: for agent and Re-triage
Cells (global mode, maintainer checklist)Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36816092864 (ubuntu, macos and windows × Ruby 2.7 / 3.3 / 3.4).
Other cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: handover from the Composer bug-hunt routine (lead, unverified for gem) While I was confirming #438 (Composer, Windows), the root cause turned out to be Composer evidence: #438 and the probe run https://github.com/SocketDev/socket-patch/actions/runs/36827949605 |
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: a hold-open copy of Re-triage
Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: a copy of Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Bundler (RubyGems) bug-hunt routine (label pm:bundler).
Last updated: 2026-10-01 (run 6), main
61cfb9b, latest release tag v4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (the sandbox blocks the real one) around real
gem buildfixtures, followed by a realbundle installon a fresh checkout. The repo's own e2e suites (e2e_redirect_gem_build.rs,e2e_vendor_gem_build.rs,e2e_redirect_gem_stale_install.rs) already cover the plain single-line Gemfile cells across 1.17 → 4.x. This ledger tracks what they don't.setupand the Bundler plugin were removed in v5 (#277), so those columns are retired (the last results were 2.2–2.4 fail #389 → closed, and 2.5 / 4.x pass).Project modes
ifmodifiergroupblockBUNDLE_GEMFILEin.bundle/configGemfileonlygems.rb+GemfiletwinBUNDLE_GEMFILEgems.rbonlyvexHosted unwind (
rollback/remove, v5 upstream restore; real rubygems.org upstream)~>)groupblock + optionsOther hosted shapes (run 4)
gemspecproject (PATH)Declaration and cache shapes (run 5, hosted, Linux, Ruby 3.3.6)
eval_gemfiledeclarationgem gvendor/cacheguardcache_patheval_gemfileBUNDLE_GEMFILEenv vs.bundle/config(run 6, Linux, Ruby 3.3.6)Gemfile.next+ envGemfileGemfile.nextGemfile.nextGlobal mode (
-g)scan -greport-gvs project scopingscan -g --mode hostedrefusedget -g/apply -grollback -gbyte-exactvex -g--global-prefix <gems dir>/SOCKET_GLOBAL=1Permission denied)--global-prefixpass;SOCKET_GLOBAL=1fail #421--global-prefixpassBacklog
-g) mode on every major version and OS. Remaining: macOS system Ruby and Homebrew Ruby; rbenv / rvm / chruby / asdf layouts; unicode or space-containing--global-prefix; a non-writable dir on macOS and Windows (Program Files);-gfrom inside a project on macOS and Windows. Re-check On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 once Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442 merges.BUNDLE_GEMFILEenv var override.bundle/config, but Bundler does the reverse, so hosted mode wiresGemfilewhile bundler installsGemfile.nextunpatched and VEX attests it #507 (vendor/gem.rs:149), driven through a copy ofe2e_vendor_gem_build.rs.eval_gemfile/ loop declaration (the sibling of Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 atvendor/gem.rs).BUNDLE_CACHE_PATHfrom the environment (Gem hosted stale-install guard only checksvendor/cache, so a committed cache at a configuredcache_pathgets no warning, the in-run VEX attests it, and Bundler 2.4 installs the unpatched gem #483's variant);vendor/cache+rollback.gemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 on Bundler 2.2–2.5 (Linux); re-run Hosted gem redirect breaks a multi-linegemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 / Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 once the Gemfile rewriter changes.BUNDLE_PATH): does On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 hide the project's gems too?BUNDLE_PATHwith a drive letter or spaces,x64-mingw-ucrtplatform gems, andvendor/bundledeployment mode.scanfrom a subdirectory of a Bundler project.Known non-bugs
patches-api.socket.dev/api.socket.devare blocked from the sandbox. Use a local mock API (--api-url,--api-token fake --org org). A ~60-line Python mock serving/v0/orgs/org/patches/{batch,view/<uuid>,by-package/…}withblobContentis enough for agent and-gflows; for hosted, use a hold-open copy ofe2e_redirect_gem_build.rs.--vendor-source buildis gone). To drive vendored cells, copye2e_vendor_gem_build.rs(itsprebuilt_commonfixture serves the artifact) rather than calling the CLI by hand:vendor --offlinewithout a prestaged artifact fails withvendor_service_offline_conflict, which is expected.--global-prefixtakes the package-leaf dir (<gem home>/gems), likenode_modules/site-packagesfor the other ecosystems. Pointing it at the gem home itself scans 0 packages; that's the convention, not a bug.-gagent runs keep their manifest at<cwd>/.socket/manifest.json, androllback -gremoves the entry.vex -gthen needs a freshget -gplus--product(no project to auto-detect from).bundler/gems/<name>-<sha>) isn't crawled in agent mode. Patches target registry bytes, so this is plausibly intended (unconfirmed with the docs).gems.rb-only project can't vendor. It's documented, and the refusal isno Gemfile at …/Gemfile.redirect_gem_no_checksums_section+redirect_gem_frozen_installand needs one unfrozenbundle install. Documented.-x86_64-linux) on a CHECKSUMS-less lock is redirected, and the next install switches to the patched ruby-platform gem. It's intended. With CHECKSUMS it fails closed (redirect_gem_platform_unsupported).bundle install --deploymentexits 15 on Bundler 4 (the flag was removed). UseBUNDLE_DEPLOYMENT=true/--frozen.sourceblock inside agroup … doblock dedents it. Cosmetic.rollback/removerefuse a gem whose upstreamGEMremote isn't rubygems.org (its CHECKSUMS can't be re-derived). To test the restore, use a real rubygems.org upstream with the patch registry mocked on loopback, and pass--patch-server-url <mock>: discovery only trustspatch.socket.devor that origin.rollback, a direct dep's original constraint (~> 1.1) comes back as the exact pin"1.1.0". That's documented in "Hosted unwind coverage".rollbackreportsManifest not found. The pin is Gemfile-only, which is documented as out of the restore's reach.bundle lock --add-checksumsto get the converged shape.^\s*gemmatch). That's cosmetic, androllbackre-derives the layout.git push --deletegets 403 from the git proxy).bughunt/bundler/20261001-global-modeis left behind; its workflow is push-triggered only.scan --vextakes--vex-product, not--product(that'svex's flag). Without either, a gem project fails withproduct_undetected.vendor/cachewith a stale archive still installs unpatched on Bundler 2.4 after the hosted scan. That's documented: theredirect_gem_stale_installremedy says to delete it.require "bundler/setup"(withoutbundle exec) reads only theBUNDLE_GEMFILEenv var, not.bundle/config; the CLI commands (install,lock,exec) let.bundle/configwin. Gem manifest resolution lets theBUNDLE_GEMFILEenv var override.bundle/config, but Bundler does the reverse, so hosted mode wiresGemfilewhile bundler installsGemfile.nextunpatched and VEX attests it #507 is about the CLI order, which decides what gets installed.All reactions